Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW - Data Center Virtualization
NEW - Air Force ELSG Contract Guide
NEW - Security Management
NEW - DOD and Security Guide
Networx Contract Guide
SEWP IV Contract Guide
Priority Report: Virtualization
NEW - CHESS formerly ASCP
New - SATCOM II

More >>



Latest News
ADVERTISEMENT





 

Davis: FISMA could prevent 'cyber Pearl Harbor'

By Matthew Weigelt
Published on April 27, 2006

Comment

Click here to comment on this article


Related story links

Anti-terrorism agencies get lowest grades

Risk management critical for FISMA success

Security grades bring new complaints


Newsletters

You might also be interested in these FCW newsletters:

Daily

To learn more, click here.


Rep. Tom Davis (R-Va.) predicted a “cyber Pearl Harbor,” an attack in the future that would penetrate the federal government in some way. He said such an attack could cause deaths or a financial breakdown. That is why the Federal Information Security Management Act’s standards are necessary as preventive measures, despite needing tweaks and improvements, he said at an Industry Advisory Council and American Council for Technology luncheon in Washington, D.C. “It’s difficult, I think, for managers out there when you get so much thrown at you,” Davis said. “You’ve got a lot of boxes to check.” However, the standards will be forced through appropriations as lawmakers start to cooperate, he said. Davis said he is open to feedback on FISMA requirements. The House Government Reform Committee, which Davis heads, releases a FISMA report card annually, grading each agency on its compliance with FISMA standards. It released its 2005 report card March 16. This year, the federal government as a whole had a D-plus for computer security. Karen Evans, administrator of e-government and information technology at the Office of Management and Budget, said after the luncheon that officials are discussing the controversy over whether the security certification and accreditation standards meet the legislation’s intended goals or whether FISMA is seen simply as a requirement. She said she believes that meeting standards is beneficial, “if you do it in the spirit in which it was intended.” Evans directed questions about possible upcoming changes to FISMA to Davis’ committee. According to the latest assessment of federal agencies’ FISMA compliance, weaknesses and inconsistencies in agencies’ security management practices left dangerous holes in critical infrastructures. Notably, agencies whose missions include homeland security received failing grades in 2005. Grades for the Defense, Homeland Security, Justice and State departments remained below average or dropped. Of those four departments, DHS remained level with its 2004 grade of an F, according to the committee’s rating. The other departments’ grades fell from the previous year. DOD went from a D to an F, Justice dropped from a B-minus to a D and State fell from a D-plus to an F. “FISMA is still viewed by some federal agencies as a paperwork exercise,” Davis said at a congressional hearing in March, when the committee released the grades. “But these are shortsighted observations.”

upcoming event

Enterprise Architecture 2008 - Washington, DC
September 9 - September 10, 2008

Occupational Health & Safety Executive Summit - Arlington, VA
October 6 - October 7, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email